security research
iltosec
ILTOSEC
writeups & research

Blog

RSS
21 posts
/
categories
tags
CVE·Vulnerability Research · CVE
CVE-2026-48492: User Account Enumeration via Missing Authorization in Snipe-IT
Technical breakdown of CVE-2026-48492: A missing authorization flaw in Snipe-IT allowing authenticated users to enumerate accounts via the API.
2026-05-27
956 4 3 min read
Rce·CVE · Rce
FacturaScripts <= 2026 Authenticated RCE via Malicious Plugin Upload
Detailed vulnerability analysis of an Authenticated Remote Code Execution (RCE) in FacturaScripts (<= 2026). Explore the PoC via malicious plugin upload and learn about server hardening mitigations.
2026-05-01
363 2 3 min read
Rce·File Upload Bypass·Command Injection · Rce·CMS·File Upload Bypass
EspoCRM v9.3.4 Authenticated Remote Code Execution via Malicious Extension Upload
Explore the technical analysis of the Authenticated Remote Code Execution (RCE) vulnerability in EspoCRM <= v9.3.4. Learn how malicious extension uploads can lead to full OS command execution and find mitigation strategies. Official PoC and exploit details included.
2026-04-13
483 1 3 min read
Rce·CVE · Rce·CMS
.NET Deserialization Leading to Remote Code Execution (CVE-2019-18211)
This blog post explains the black-box exploitation of Composite C1 CMS via CVE-2019-18211. The deserialization vulnerability in the EntityTokenSerializer class allows attackers to achieve remote code execution (RCE) on the server. Step-by-step attack and mitigation recommendations are provided.
2025-08-15
1427 13 3 min read
SSTI·Rce·Command Injection · Rce
Whitebox Web Pentesting: Exploiting Flask Authentication & RCE in Chain Lab
A detailed walkthrough of **Chain Lab** from **CyberExam.io**, demonstrating a Flask web app's **authentication bypass**, **SQL injection**, **hash cracking**, and **RCE exploitation**. Learn how to chain web vulnerabilities for real-world penetration testing.
2025-05-06
1615 9 2 min read
Rce·File Upload Bypass·Authentication Bypass · Rce·File Upload Bypass
Exploiting Flask Authentication and RCE Vulnerabilities – Chain Lab Writeup
Learn how to exploit Flask authentication and remote code execution (RCE) vulnerabilities in the Chain Lab challenge on CyberExam. This step-by-step writeup demonstrates bypassing Flask session authentication, uploading a reverse shell payload, and gaining full control over the system.
2024-12-02
9846 11 4 min read
Host Header Injection · CMS
Host Header Injection Vulnerability in Plone CMS 6.0.13 - A Security Risk for Password Reset Process
Learn about the Host Header Injection vulnerability in Plone CMS 6.0.13, its impact on password reset emails and URL redirection, and recommended mitigations to protect your web application from malicious attacks.
2024-11-27
1655 4 4 min read
CVE·File Upload Bypass · CVE·File Upload Bypass
CVE-2024-11404: Medium Severity File Upload Vulnerabilities in django-filer 3.2.3
Unrestricted Upload of File with Dangerous Type, Improper Input Validation, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS.This issue affects django Filer: from 3 before 3.3.
2024-11-20
5717 2 5 min read
Ransomware · Ransomware
What is Ransomware, How Does It Work, How Can We Be Protected?
Discover what ransomware is, how it works, its history, famous ransomware attacks, and effective strategies to protect yourself and your business from this dangerous malware.
2024-11-19
1166 3 7 min read
Xss·CVE · CMS·CVE
Django CMS 4.1.3 Stored XSS Vulnerability: Exploiting the Page Title Field
CVE-2024-11319 Discover the stored XSS vulnerability in Django CMS 4.1.3 that affects the Page Title field. Learn about the security risks, exploitation methods, and remediation strategies to protect your site from potential attacks. CVE-2024-11319 stored XSS vulnerability, Django CMS 4.1.3, CVE-2024-11319, JavaScript injection, Django CMS 4.1.3 CVE-2024-11319, admin panel security, Cross-Site Scripting, security patch, CVE, content security policy, input sanitization
2024-11-11
5189 15 3 min read
← prev 1 2 3 next →